OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Admin Command Injection Vulnerability in LiteSpeed OpenLiteSpeed and LSWS Enterprise |
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litespeed Technologies
Litespeed Technologies lsws Enterprise Litespeed Technologies openlitespeed |
|
| Vendors & Products |
Litespeed Technologies
Litespeed Technologies lsws Enterprise Litespeed Technologies openlitespeed |
Mon, 16 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2026-03-16T05:21:13.948Z
Updated: 2026-03-16T15:29:03.838Z
Reserved: 2026-03-09T09:07:18.132Z
Link: CVE-2026-31386
Updated: 2026-03-16T15:28:59.211Z
Status : Awaiting Analysis
Published: 2026-03-16T14:19:33.170
Modified: 2026-03-16T14:53:07.390
Link: CVE-2026-31386
No data.